The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the drop filter settings using the CLI

Prev Next

Use the CLI commands in this procedure to enable or disable each type of drop filter setting.

Note

You must use the policymgr interface <port-pair-name> re-configure command for the changes to take effect.

To enable each type of drop filter setting on an appliance interface:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable sending a TCP reset message for the relevant operational mode.

    hostname (config) # policymgr interface <port-pair-name> drop tcp reset enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  3. Enable sending a TCP reset message to the client for the relevant operational mode.

    hostname (config) # policymgr interface <port-pair-name> drop tcp reset client enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  4. Enable sending a TCP reset message to the server for the relevant operational mode.

    hostname (config) # policymgr interface <port-pair-name> drop tcp reset server enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  5. Enable sending an icmp-port-unreachable message to the sender for the relevant operational mode.

    hostname (config) # policymgr interface <port-pair-name> drop udp icmpport-unreachable enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  6. Specify when a specific A or B monitoring interface is configured for out-of-band tap mode blocking with TCP reset, UDP, or HTTP-enabled.

    • To specify blocked packets that are sent on outbound traffic by the Network Security appliance to the ether1 management interface:

      hostname (config) # policymgr interface <port-pair-name> drop out-interface ether1

      where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

    • To specify blocked packets that are sent on outbound traffic by the Network Security appliance to the ether2 management interface:

      hostname (config) # policymgr interface <port-pair-name> drop out-interface ether2

      where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  7. Enable posting an HTTP comfort page to the HTTP requester.

    hostname (config) # policymgr interface <port-pair-name> drop http comfort-page enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  8. Specify a comfort page message.

    • To specify an access-denied (response type 401) message:

      hostname (config) # policymgr interface <port-pair-name> drop http comfort-page response-type access-denied [message <message>]

      where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface and <message> (optional) specifies the text of the message.

    • To specify an access-forbidden (response type 403) message:

      hostname (config) # policymgr interface <port-pair-name> drop http comfort-page response-type access-forbidden [message <message>]

      where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface and <message> (optional) specifies the text of the message.

  9. Reapply the configuration to the specified interface.

    hostname (config) # policymgr interface <port-pair-name> re-configure
    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.
  10. Verify the status of the drop filter configuration settings.

    hostname (config) # show policymgr drop configuration
    Policy drop filter configuration:
    ...
    HTTP Comfort Page:
     Enabled        : yes
    Type           : access-denied
    Message        : The page you are trying to access, http://%U, has a potential threat detected.
    TCP Reset        :
    Enabled        : yes
    to Server      : yes
    to Client      : yes
    UDP ICMP Port-Unreachable:
    Enabled        : yes
  11. Save your changes.

    hostname (config) # write memory
    Saving configuration file ... Done!
To disable each type of drop filter setting on an appliance interface:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Disable sending a TCP reset message for the relevant operational mode.

    hostname (config) # no policymgr interface <port-pair-name> drop tcp reset enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  3. Disable sending a TCP reset message to the client for the relevant operational mode.

    hostname (config) # no policymgr interface <port-pair-name> drop tcp reset client enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  4. Disable sending a TCP reset message to the server for the relevant operational mode.

    hostname (config) # no policymgr interface <port-pair-name> drop tcp reset server enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  5. Disable sending an icmp-port-unreachable message to the sender for the relevant operational mode.

    hostname (config) # no policymgr interface <port-pair-name> drop udp icmpport-unreachable enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  6. Disable posting an HTTP comfort page to the HTTP requester.

    hostname (config) # no policymgr interface <port-pair-name> drop http comfort-page enable

    where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.

  7. Verify the status of the drop filter configuration settings.

    hostname (config) # show policymgr drop configuration
    Policy drop filter configuration:
    ...
    HTTP Comfort Page:
    Enabled        : no
    Type           : access-denied
    Message        : The page you are trying to access, http://%U, has a potential threat detected.
    TCP Reset        :
    Enabled        : no
    to Server      : no
    to Client      : no
    UDP ICMP Port-Unreachable:
    Enabled        : no
  8. Save your changes.

    hostname (config) # write memory
    Saving configuration file ... Done!